Записи SonicWall
236 опубликованных записей вендора sonicwall.
Профиль для исследователя
- Попали в KEV
- 23 · 9,7 %
- С эксплойтом
- 36 · 15,3 %
- Pre-auth RCE
- 22
- С записью об исправлении
- 5,5 %
- Медиана: публикация → KEV
- 197 дн.
Повторяющиеся классы
- CWE-121 Stack-based Buffer Overflow23
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')12
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')12
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')12
- CWE-287 Improper Authentication9
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
236 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2021-44228Готовый эксплойт | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Критическая10,0 | KEV | 100,0 % | 10 дек. 2021 г. |
99Срочно | CVE-2021-20038Готовый эксплойт | A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticsonicwall · sma 200 firmware · CWE-121 | Критическая9,8 | KEV | 99,9 % | 8 дек. 2021 г. |
98Срочно | CVE-2024-53704Готовый эксплойт | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.sonicwall · sonicos · CWE-287 | Критическая9,8 | KEV | 95,1 % | 9 янв. 2025 г. |
96Срочно | CVE-2021-45046Готовый эксплойт | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Критическая9,0 | KEV | 100,0 % | 14 дек. 2021 г. |
96Срочно | CVE-2024-38475Готовый эксплойт | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.apache · http server · CWE-116 | Критическая9,1 | KEV | 100,0 % | 1 июл. 2024 г. |
96Срочно | CVE-2021-20021Готовый эксплойт | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a craftedsonicwall · email security · CWE-269 | Критическая9,8 | KEV | 88,7 % | 9 апр. 2021 г. |
90Срочно | CVE-2019-7481Готовый эксплойт | Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources.sonicwall · sma 100 firmware · CWE-89 | Высокая7,5 | KEV | 99,9 % | 17 дек. 2019 г. |
89Срочно | CVE-2022-0847Готовый эксплойт | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe linux · linux kernel · CWE-665 | Высокая7,8 | KEV | 92,8 % | 10 мар. 2022 г. |
81Срочно | CVE-2023-44221Готовый эксплойт | Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrsonicwall · sma 200 firmware · CWE-78 | Высокая7,2 | KEV | 76,3 % | 5 дек. 2023 г. |
81Срочно | CVE-2021-20016Готовый эксплойт | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to accesssonicwall · sma 100 firmware · CWE-89 | Критическая9,8 | KEV | 40,0 % | 4 февр. 2021 г. |
78На этой неделе | CVE-2021-20028Готовый эксплойт | Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, ssonicwall · sma 210 firmware · CWE-89 | Критическая9,8 | KEV | 30,1 % | 4 авг. 2021 г. |
77На этой неделе | CVE-2020-5135Готовый эксплойт | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code sonicwall · sonicos · CWE-120 | Критическая9,8 | KEV | 26,9 % | 12 окт. 2020 г. |
76На этой неделе | CVE-2025-23006Готовый эксплойт | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) andsonicwall · sma8200v · CWE-502 | Критическая9,8 | KEV | 23,4 % | 23 янв. 2025 г. |
75На этой неделе | CVE-2024-40766Готовый эксплойт | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorizedsonicwall · sonicos · CWE-284 | Критическая9,8 | KEV | 18,4 % | 23 авг. 2024 г. |
73На этой неделе | CVE-2026-83548Готовый эксплойт | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.sonicwall · sma8200v · CWE-441 | Критическая10,0 | KEV | 8,8 % | 1 сент. 2026 г. |
72На этой неделе | CVE-2026-15409Готовый эксплойт | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.sonicwall · sma6210 firmware · CWE-918 | Критическая10,0 | KEV | 6,8 % | 14 июл. 2026 г. |
66На этой неделе | CVE-2013-1359Готовый эксплойт | An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Unsonicwall · analyzer · CWE-287 | Критическая9,8 | — | 89,4 % | 11 февр. 2020 г. |
64На этой неделе | CVE-2021-20023Готовый эксплойт | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on thsonicwall · email security · CWE-22 | Средняя4,9 | KEV | 51,4 % | 20 апр. 2021 г. |
64На этой неделе | CVE-2026-83549Готовый эксплойт | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identisonicwall · sma8200v · CWE-78 | Высокая7,8 | KEV | 10,8 % | 1 сент. 2026 г. |
63На этой неделе | CVE-2021-20022Готовый эксплойт | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to sonicwall · email security · CWE-434 | Высокая7,2 | KEV | 16,5 % | 9 апр. 2021 г. |
62На этой неделе | CVE-2024-6387Proof of concept | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | Высокая8,1 | — | 99,5 % | 1 июл. 2024 г. |
62На этой неделе | CVE-2022-22274Proof of concept | A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Servsonicwall · sonicos · CWE-121 | Критическая9,8 | — | 75,5 % | 25 мар. 2022 г. |
62На этой неделе | CVE-2019-12255Proof of concept | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4).windriver · vxworks · CWE-120 | Критическая9,8 | — | 75,3 % | 9 авг. 2019 г. |
62На этой неделе | CVE-2026-15410Готовый эксплойт | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Mansonicwall · sma6210 firmware · CWE-94 | Высокая7,2 | KEV | 11,8 % | 14 июл. 2026 г. |
61На этой неделе | CVE-2023-34127Готовый эксплойт | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytisonicwall · analytics · CWE-78 | Высокая8,8 | — | 86,5 % | 12 июл. 2023 г. |
- CVE-2021-44228100Срочно
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %apache · log4j10 дек. 2021 г.
- CVE-2021-2003899Срочно
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthentic
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %sonicwall · sma 200 firmware8 дек. 2021 г.
- CVE-2024-5370498Срочно
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %sonicwall · sonicos9 янв. 2025 г.
- CVE-2021-4504696Срочно
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %apache · log4j14 дек. 2021 г.
- CVE-2024-3847596Срочно
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %apache · http server1 июл. 2024 г.
- CVE-2021-2002196Срочно
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 89 %sonicwall · email security9 апр. 2021 г.
- CVE-2019-748190Срочно
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %sonicwall · sma 100 firmware17 дек. 2019 г.
- CVE-2022-084789Срочно
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 93 %linux · linux kernel10 мар. 2022 г.
- CVE-2023-4422181Срочно
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administr
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 76 %sonicwall · sma 200 firmware5 дек. 2023 г.
- CVE-2021-2001681Срочно
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 40 %sonicwall · sma 100 firmware4 февр. 2021 г.
- CVE-2021-2002878На этой неделе
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, s
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 30 %sonicwall · sma 210 firmware4 авг. 2021 г.
- CVE-2020-513577На этой неделе
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 27 %sonicwall · sonicos12 окт. 2020 г.
- CVE-2025-2300676На этой неделе
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 23 %sonicwall · sma8200v23 янв. 2025 г.
- CVE-2024-4076675На этой неделе
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 18 %sonicwall · sonicos23 авг. 2024 г.
- CVE-2026-8354873На этой неделе
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 9 %sonicwall · sma8200v1 сент. 2026 г.
- CVE-2026-1540972На этой неделе
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 7 %sonicwall · sma6210 firmware14 июл. 2026 г.
- CVE-2013-135966На этой неделе
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Un
КритическаяCVSS 9,8Готовый эксплойтEPSS 89 %sonicwall · analyzer11 февр. 2020 г.
- CVE-2021-2002364На этой неделе
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on th
СредняяCVSS 4,9KEVГотовый эксплойтEPSS 51 %sonicwall · email security20 апр. 2021 г.
- CVE-2026-8354964На этой неделе
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identi
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 11 %sonicwall · sma8200v1 сент. 2026 г.
- CVE-2021-2002263На этой неделе
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 17 %sonicwall · email security9 апр. 2021 г.
- CVE-2024-638762На этой неделе
Openssh: regresshion - race condition in ssh allows rce/dos
ВысокаяCVSS 8,1Proof of conceptEPSS 100 %sonicwall · sma 6200 firmware1 июл. 2024 г.
- CVE-2022-2227462На этой неделе
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Serv
КритическаяCVSS 9,8Proof of conceptEPSS 76 %sonicwall · sonicos25 мар. 2022 г.
- CVE-2019-1225562На этой неделе
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4).
КритическаяCVSS 9,8Proof of conceptEPSS 75 %windriver · vxworks9 авг. 2019 г.
- CVE-2026-1541062На этой неделе
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Man
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 12 %sonicwall · sma6210 firmware14 июл. 2026 г.
- CVE-2023-3412761На этой неделе
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analyti
ВысокаяCVSS 8,8Готовый эксплойтEPSS 86 %sonicwall · analytics12 июл. 2023 г.